# How to authorize http api using post with username and password

**URL:** <https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634>\
**Category:** General\
**Created:** [14 May 2020 07:38 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634 "2020-05-14T07:38:03Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Leeches](https://avatars.discourse-cdn.com/v4/letter/l/edb3f5/32.png) [@Leeches](https://discourse.nodered.org/u/Leeches)\
**Post date:** [14 May 2020 07:38 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/1 "2020-05-14T07:38:03Z")

</div>

Hello guys,

I was trying to achieve something like that last few days..

What do I need. I need to POST data from api to obtain sessionId so I can use api further. Sadly I didn't even achieve to succesfully get 200 response from the api.

Could anyone tell me if I am missing some kind of node?

Curl : curl -X POST "[https://api.com/cxf/api/v2/Login](https://api.com/cxf/api/v2/Login)" -H "accept: application/json" -H "Content-Type: application/json" -d "{"username":"string","password":"string"}"

C# where it is working as well:

```
            using (var requestToken = new HttpRequestMessage(new HttpMethod("POST"), "https://api.com/cxf/api/v2/Login"))
            {
                requestToken.Headers.TryAddWithoutValidation("Accept", "application/json");

                requestToken.Content = new StringContent("{\"username\":\"username\",\"password\":\"password\"}", Encoding.UTF8, "application/json");

```

I was trying simple http request with basic authentication / request with added headers.

Anyone who could help me?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [14 May 2020 07:57 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/2 "2020-05-14T07:57:29Z")

</div>

Maybe it has something to do with this?

 ![Screenshot_20200514-085620](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/f/d/fdf94bf432dbffe7b63b38178a0e696dcd77058c.jpeg)

---

<div class="post-metadata">

**Author:** ![Leeches](https://avatars.discourse-cdn.com/v4/letter/l/edb3f5/32.png) [@Leeches](https://discourse.nodered.org/u/Leeches)\
**Post date:** [14 May 2020 08:07 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/3 "2020-05-14T08:07:01Z")

</div>

The address what I typed above is not correct. I am not providing the address how it supposed to be. I am sorry. But there is username and password anyway so it wouldn't work.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [14 May 2020 08:13 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/4 "2020-05-14T08:13:35Z")

</div>

> [@Leeches](#):
>
> What do I need. I need to POST data from api to obtain sessionId so I can use api further. Sadly I didn't even achieve to succesfully get 200 response from the api.

What did your flow look like? Can you post your flow (you can remove any sensitive info)

> [@Leeches](#):
>
> Could anyone tell me if I am missing some kind of node?

Not at far as I can tell. You haven't really provided enough info. I mean it's good you have proof the API works (let's us know you know what you're doing) but you haven't shown what you did in node-red.

---

<div class="post-metadata">

**Author:** ![Leeches](https://avatars.discourse-cdn.com/v4/letter/l/edb3f5/32.png) [@Leeches](https://discourse.nodered.org/u/Leeches)\
**Post date:** [14 May 2020 08:22 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/5 "2020-05-14T08:22:08Z")

</div>

Okay, so what I was trying to do in my flow is.

Http request where I using basic authentication then I was trying to format it into json and print it.

 ![nodered](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/f/8f570532dfb64a9eebee0332d4b999287d6b4e83.png)

the 415 status code showed when I tried to use output as a complete msg. When I use just .msg it shows nothing

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [14 May 2020 08:29 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/6 "2020-05-14T08:29:46Z")

</div>

> The HTTP 415 Unsupported Media Type client error response code indicates that the server refuses to accept the request because the payload format is in an unsupported format. The format problem might be due to the request's indicated Content-Type or Content-Encoding

Does that help?

Lastly, as you haven't posted your flow I can't check headers etc.

---

<div class="post-metadata">

**Author:** ![Leeches](https://avatars.discourse-cdn.com/v4/letter/l/edb3f5/32.png) [@Leeches](https://discourse.nodered.org/u/Leeches)\
**Post date:** [14 May 2020 08:33 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/7 "2020-05-14T08:33:30Z")

</div>

```auto
[{"id":"85ff2371.2062","type":"tab","label":"Flow 1","disabled":false,"info":""},{"id":"ef1fb1a6.fe39b","type":"inject","z":"85ff2371.2062","name":"","topic":"","payload":"","payloadType":"str","repeat":"300","crontab":"","once":false,"onceDelay":"","x":290,"y":200,"wires":[["860cc555.a00e38"]]},{"id":"860cc555.a00e38","type":"http request","z":"85ff2371.2062","name":"Login","method":"POST","ret":"txt","paytoqs":false,"url":"api","tls":"","persist":false,"proxy":"","authType":"","x":490,"y":200,"wires":[["9e84dae6.4e53b8"]]},{"id":"463b47a.98546b8","type":"debug","z":"85ff2371.2062","name":"","active":true,"tosidebar":true,"console":false,"tostatus":true,"complete":"true","targetType":"full","x":850,"y":200,"wires":[]},{"id":"9e84dae6.4e53b8","type":"json","z":"85ff2371.2062","name":"","property":"payload","action":"","pretty":true,"x":670,"y":200,"wires":[["463b47a.98546b8"]]}]

```

Here is my import string.

I found data about 415 as well. But honestly I don't know what to do with it since it is working for me in C# without any fancy modifications

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [14 May 2020 08:42 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/8 "2020-05-14T08:42:56Z")

</div>

I'll take a look in just a minute but please use the forum for pasting flows.

`````  
`paste code directly into reply between backticks like this`  
`````

---

<div class="post-metadata">

**Author:** ![afelix](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/afelix/32/9743_2.png) [@afelix](https://discourse.nodered.org/u/afelix)\
**Post date:** [14 May 2020 08:48 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/9 "2020-05-14T08:48:59Z")

</div>

Looking at your C# code, you should not use basic auth in your http request node. Instead, use a change or function node before it and use it to set `msg.headers` to `{'Content-Type': 'application/json'}`, and the payload to an object with the username/password values. Make sure the method is POST and try again.

The request is simply a json object posted to that endpoint. Basic auth sets the username and password values base64 encoded in an Authorization header. That’s not what’s going on here.

Same when looking at the curl. No basic auth there either, just an object sent as body of the POST request.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [14 May 2020 08:52 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/10 "2020-05-14T08:52:30Z")

</div>

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/f/4f97fb0eab7522b7616213bad26fc1dfd78a66a6.png)

~~You dont specify content type in the headers, you probably need to add `headers` to the msg. (info is in the built in documentation of the http request node)~~

Never mind - look at what @afelix posted ^

---

<div class="post-metadata">

**Author:** ![afelix](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/afelix/32/9743_2.png) [@afelix](https://discourse.nodered.org/u/afelix)\
**Post date:** [14 May 2020 08:53 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/11 "2020-05-14T08:53:40Z")

</div>

But also look at what Steve posted because the content type for the body is application/json by default 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [13 July 2020 08:53 UTC](https://discourse.nodered.org/t/how-to-authorize-http-api-using-post-with-username-and-password/26634/12 "2020-07-13T08:53:40Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
